summaryrefslogtreecommitdiff
path: root/swamid-interfederations-2.0/idp.chalmers.se-adfs-services-trust.xml
diff options
context:
space:
mode:
Diffstat (limited to 'swamid-interfederations-2.0/idp.chalmers.se-adfs-services-trust.xml')
-rw-r--r--swamid-interfederations-2.0/idp.chalmers.se-adfs-services-trust.xml380
1 files changed, 380 insertions, 0 deletions
diff --git a/swamid-interfederations-2.0/idp.chalmers.se-adfs-services-trust.xml b/swamid-interfederations-2.0/idp.chalmers.se-adfs-services-trust.xml
new file mode 100644
index 00000000..47d0de1b
--- /dev/null
+++ b/swamid-interfederations-2.0/idp.chalmers.se-adfs-services-trust.xml
@@ -0,0 +1,380 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntityDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="http://idp.chalmers.se/adfs/services/trust">
+ <md:Extensions>
+ <mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.swamid.se/">
+ <mdrpi:RegistrationPolicy xml:lang="en">https://www.sunet.se/wp-content/uploads/2016/08/SWAMID-Metadata-Registration-Practice-Statement-v2.pdf</mdrpi:RegistrationPolicy>
+ </mdrpi:RegistrationInfo>
+ <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <saml:AttributeValue>http://www.swamid.se/policy/assurance/al1</saml:AttributeValue>
+ </saml:Attribute>
+ </mdattr:EntityAttributes>
+ </md:Extensions>
+ <md:RoleDescriptor xmlns:fed="http://docs.oasis-open.org/wsfed/federation/200706" xsi:type="fed:ApplicationServiceType" protocolSupportEnumeration="http://docs.oasis-open.org/ws-sx/ws-trust/200512 http://schemas.xmlsoap.org/ws/2005/02/trust http://docs.oasis-open.org/wsfed/federation/200706" ServiceDisplayName="idp.chalmers.se">
+ <md:KeyDescriptor use="encryption">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEgjCCA2qgAwIBAgIRAJmWfwVBm8cQS1Ty7e6QuJgwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMTAxMjcwMDAwMDBaFw0xNDAxMjYyMzU5NTlaMF0xCzAJBgNVBAYTAlNFMSYwJAYDVQQKEx1DaGFsbWVycyBUZWtuaXNrYSBIb2dza29sYSBBQjEMMAoGA1UECxMDSVRTMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj5S9nh00xzrsXmphDbOz4RPwG0JONHrBtVOm6NNwTTQhl8eZSG4oIT/ATXAaQjGXAnz04HDShP6xKwsPN0wZTpuEci4XLlbUaWvcuefPAwGO8Be/HWEB03ilM+FLmJ55CYvpFfxbuElA30YzQcw2xU637g/+rshELRCMZB9Thp3j0tZ09sQTXbodnStm3hN0azuqvtXhZ63+q47GpocyiOlj7wHY6zZ4OfCj2YxFIeiLBBur6/mBKH3uA/xkuIv6NPAN+BI0L4iH1q+umCjeE/qfzWLO3Fe3ngYTWx0YFEIduRWCz7fyLUITNJBSK7YENFdIB0g8wXBWcTVpAv08RAgMBAAGjggFiMIIBXjAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQU6ZdOotf55GTP/djvkXZgjXBGSqQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBgGA1UdIAQRMA8wDQYLKwYBBAGyMQECAh0wOgYDVR0fBDMwMTAvoC2gK4YpaHR0cDovL2NybC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcmwwbQYIKwYBBQUHAQEEYTBfMDUGCCsGAQUFBzAChilodHRwOi8vY3J0LnRjcy50ZXJlbmEub3JnL1RFUkVOQVNTTENBLmNydDAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AudGNzLnRlcmVuYS5vcmcwGgYDVR0RBBMwEYIPaWRwLmNoYWxtZXJzLnNlMA0GCSqGSIb3DQEBBQUAA4IBAQBsPH77mopZLCpQgcrIYyZJfGKrXb7rQ4NNaBOR8o/KLNptvY7NPtOnu0HRJrYfZIx4Abj0VgDs/CBWSnBJQcE+aGMQmcPhrSDua9S5p+Cpq4AV7bhCRIovWPFPNQ7TTYRKCkFCmnkM/Y3EyliddxM1JsIL5rw+k8/O/KUJPCSff7yDsSmse5qUrJ12Nh+aG/MB4NknOJuAsLjs0HpIjdVTNFb9dbhrE+8x3AiL0Nk9G69gff1V7uxndvWhCoDUW3RVkpj9xssfHj4atp9F7t3q0bKdt7Y3HWQm8wpSJd7OUWI2WXbA6kjI2YZtFcUCOzy32crsMxLXKsHJyMp/XYyw</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <fed:ClaimTypesRequested>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" Optional="true">
+ <auth:DisplayName>E-Mail Address</auth:DisplayName>
+ <auth:Description>The e-mail address of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" Optional="true">
+ <auth:DisplayName>Given Name</auth:DisplayName>
+ <auth:Description>The given name of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" Optional="true">
+ <auth:DisplayName>Name</auth:DisplayName>
+ <auth:Description>The unique name of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" Optional="true">
+ <auth:DisplayName>UPN</auth:DisplayName>
+ <auth:Description>The user principal name (UPN) of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/CommonName" Optional="true">
+ <auth:DisplayName>Common Name</auth:DisplayName>
+ <auth:Description>The common name of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/EmailAddress" Optional="true">
+ <auth:DisplayName>AD FS 1.x E-Mail Address</auth:DisplayName>
+ <auth:Description>The e-mail address of the user when interoperating with AD FS 1.1 or ADFS 1.0</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/Group" Optional="true">
+ <auth:DisplayName>Group</auth:DisplayName>
+ <auth:Description>A group that the user is a member of</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/UPN" Optional="true">
+ <auth:DisplayName>AD FS 1.x UPN</auth:DisplayName>
+ <auth:Description>The UPN of the user when interoperating with AD FS 1.1 or ADFS 1.0</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" Optional="true">
+ <auth:DisplayName>Role</auth:DisplayName>
+ <auth:Description>A role that the user has</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" Optional="true">
+ <auth:DisplayName>Surname</auth:DisplayName>
+ <auth:Description>The surname of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" Optional="true">
+ <auth:DisplayName>PPID</auth:DisplayName>
+ <auth:Description>The private identifier of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" Optional="true">
+ <auth:DisplayName>Name ID</auth:DisplayName>
+ <auth:Description>The SAML name identifier of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant" Optional="true">
+ <auth:DisplayName>Authentication time stamp</auth:DisplayName>
+ <auth:Description>Used to display the time and date that the user was authenticated</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod" Optional="true">
+ <auth:DisplayName>Authentication method</auth:DisplayName>
+ <auth:Description>The method used to authenticate the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid" Optional="true">
+ <auth:DisplayName>Deny only group SID</auth:DisplayName>
+ <auth:Description>The deny-only group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid" Optional="true">
+ <auth:DisplayName>Deny only primary SID</auth:DisplayName>
+ <auth:Description>The deny-only primary SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid" Optional="true">
+ <auth:DisplayName>Deny only primary group SID</auth:DisplayName>
+ <auth:Description>The deny-only primary group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid" Optional="true">
+ <auth:DisplayName>Group SID</auth:DisplayName>
+ <auth:Description>The group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid" Optional="true">
+ <auth:DisplayName>Primary group SID</auth:DisplayName>
+ <auth:Description>The primary group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid" Optional="true">
+ <auth:DisplayName>Primary SID</auth:DisplayName>
+ <auth:Description>The primary SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname" Optional="true">
+ <auth:DisplayName>Windows account name</auth:DisplayName>
+ <auth:Description>The domain account name of the user in the form of &lt;domain&gt;\&lt;user&gt;</auth:Description>
+ </auth:ClaimType>
+ </fed:ClaimTypesRequested>
+ <fed:TargetScopes>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256</Address>
+ </EndpointReference>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/services/trust/2005/issuedtokenmixedsymmetricbasic256</Address>
+ </EndpointReference>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256</Address>
+ </EndpointReference>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/services/trust/13/issuedtokenmixedsymmetricbasic256</Address>
+ </EndpointReference>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/ls/</Address>
+ </EndpointReference>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>http://idp.chalmers.se/adfs/services/trust</Address>
+ </EndpointReference>
+ </fed:TargetScopes>
+ <fed:ApplicationServiceEndpoint>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256</Address>
+ </EndpointReference>
+ </fed:ApplicationServiceEndpoint>
+ <fed:PassiveRequestorEndpoint>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/ls/</Address>
+ </EndpointReference>
+ </fed:PassiveRequestorEndpoint>
+ </md:RoleDescriptor>
+ <md:RoleDescriptor xmlns:fed="http://docs.oasis-open.org/wsfed/federation/200706" xsi:type="fed:SecurityTokenServiceType" protocolSupportEnumeration="http://docs.oasis-open.org/ws-sx/ws-trust/200512 http://schemas.xmlsoap.org/ws/2005/02/trust http://docs.oasis-open.org/wsfed/federation/200706" ServiceDisplayName="idp.chalmers.se">
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEgjCCA2qgAwIBAgIRAJmWfwVBm8cQS1Ty7e6QuJgwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMTAxMjcwMDAwMDBaFw0xNDAxMjYyMzU5NTlaMF0xCzAJBgNVBAYTAlNFMSYwJAYDVQQKEx1DaGFsbWVycyBUZWtuaXNrYSBIb2dza29sYSBBQjEMMAoGA1UECxMDSVRTMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj5S9nh00xzrsXmphDbOz4RPwG0JONHrBtVOm6NNwTTQhl8eZSG4oIT/ATXAaQjGXAnz04HDShP6xKwsPN0wZTpuEci4XLlbUaWvcuefPAwGO8Be/HWEB03ilM+FLmJ55CYvpFfxbuElA30YzQcw2xU637g/+rshELRCMZB9Thp3j0tZ09sQTXbodnStm3hN0azuqvtXhZ63+q47GpocyiOlj7wHY6zZ4OfCj2YxFIeiLBBur6/mBKH3uA/xkuIv6NPAN+BI0L4iH1q+umCjeE/qfzWLO3Fe3ngYTWx0YFEIduRWCz7fyLUITNJBSK7YENFdIB0g8wXBWcTVpAv08RAgMBAAGjggFiMIIBXjAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQU6ZdOotf55GTP/djvkXZgjXBGSqQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBgGA1UdIAQRMA8wDQYLKwYBBAGyMQECAh0wOgYDVR0fBDMwMTAvoC2gK4YpaHR0cDovL2NybC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcmwwbQYIKwYBBQUHAQEEYTBfMDUGCCsGAQUFBzAChilodHRwOi8vY3J0LnRjcy50ZXJlbmEub3JnL1RFUkVOQVNTTENBLmNydDAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AudGNzLnRlcmVuYS5vcmcwGgYDVR0RBBMwEYIPaWRwLmNoYWxtZXJzLnNlMA0GCSqGSIb3DQEBBQUAA4IBAQBsPH77mopZLCpQgcrIYyZJfGKrXb7rQ4NNaBOR8o/KLNptvY7NPtOnu0HRJrYfZIx4Abj0VgDs/CBWSnBJQcE+aGMQmcPhrSDua9S5p+Cpq4AV7bhCRIovWPFPNQ7TTYRKCkFCmnkM/Y3EyliddxM1JsIL5rw+k8/O/KUJPCSff7yDsSmse5qUrJ12Nh+aG/MB4NknOJuAsLjs0HpIjdVTNFb9dbhrE+8x3AiL0Nk9G69gff1V7uxndvWhCoDUW3RVkpj9xssfHj4atp9F7t3q0bKdt7Y3HWQm8wpSJd7OUWI2WXbA6kjI2YZtFcUCOzy32crsMxLXKsHJyMp/XYyw</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEazCCA1OgAwIBAgIQYiCzN6Gt8LkhjGEzm+oYbzANBgkqhkiG9w0BAQUFADA2MQswCQYDVQQGEwJOTDEPMA0GA1UEChMGVEVSRU5BMRYwFAYDVQQDEw1URVJFTkEgU1NMIENBMB4XDTE0MDEyMDAwMDAwMFoXDTE3MDEyNDIzNTk1OVowPTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDmWN/0UvY2KySOfg77U+ORidbq0YyqVSUxTEN5HT0WRRF/k7bdhyNp1mf8OuzefbFbTRwUyqi8BaFSdGaB2ifbyYhprchRdBXQzfS9OSzKRWQrRPPJRc7YF+h0OR2Byjy9Wkm3qzOzbv96DSihNuyhd+q+jUBUoJ+MWAj+K1/rsghrvAcKtedADR+62QaCQCkD6Pv7+njyWWAA1cJAm5KoEzXqANi3SkTwqUYB6PCMKnUBsh/w0I6Qv5lD0i/OXCZJguPhcGM5M/wSZq6iDLdtZ/EDNm82UXO3j+zBFDLSbiWuh74+/dtOyJKYZn5q9lGbhVqvFs/smAztKUSHndmbAgMBAAGjggFsMIIBaDAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQUaL0QFrip30INB0btXzbf1qhorUswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMCIGA1UdIAQbMBkwDQYLKwYBBAGyMQECAh0wCAYGZ4EMAQIBMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3JsMG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLnRjcy50ZXJlbmEub3JnMBoGA1UdEQQTMBGCD2lkcC5jaGFsbWVycy5zZTANBgkqhkiG9w0BAQUFAAOCAQEAll6pgh+zFiNIwql7sPVIQqhOCRjz1fOYfJUNAQQKiNeiWtZHC0PU7gcdKUmyDEmvdVuvMjnmuBzMCmTwYWBroWPMJCoHvWQGGTElForaG2AU7ghASUeGn2rtXdnj62dbhNhuh/yZfywKmCbRoKYsQB6/6TkmkQcXm7teOqzq3jOjlnJmMCRRSM8z7ZDI6KkcX+FFfsNR9zp76Xi3T6hsfNQJOD593JA7Ub8rX2p3YQIYLNGARfR7fAQoSBgibcGX6buthzFl1Af+ghyy99nezrJ1srvD81AKG7a55znKBcQLPTTsqMlaG9tM9ERe/wQhf9zEUBPDB8PLmA+FfmR3Mg==</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <fed:TokenTypesOffered>
+ <fed:TokenType Uri="urn:oasis:names:tc:SAML:2.0:assertion"/>
+ <fed:TokenType Uri="urn:oasis:names:tc:SAML:1.0:assertion"/>
+ </fed:TokenTypesOffered>
+ <fed:ClaimTypesOffered>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" Optional="true">
+ <auth:DisplayName>E-Mail Address</auth:DisplayName>
+ <auth:Description>The e-mail address of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" Optional="true">
+ <auth:DisplayName>Given Name</auth:DisplayName>
+ <auth:Description>The given name of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" Optional="true">
+ <auth:DisplayName>Name</auth:DisplayName>
+ <auth:Description>The unique name of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" Optional="true">
+ <auth:DisplayName>UPN</auth:DisplayName>
+ <auth:Description>The user principal name (UPN) of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/CommonName" Optional="true">
+ <auth:DisplayName>Common Name</auth:DisplayName>
+ <auth:Description>The common name of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/EmailAddress" Optional="true">
+ <auth:DisplayName>AD FS 1.x E-Mail Address</auth:DisplayName>
+ <auth:Description>The e-mail address of the user when interoperating with AD FS 1.1 or ADFS 1.0</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/Group" Optional="true">
+ <auth:DisplayName>Group</auth:DisplayName>
+ <auth:Description>A group that the user is a member of</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/claims/UPN" Optional="true">
+ <auth:DisplayName>AD FS 1.x UPN</auth:DisplayName>
+ <auth:Description>The UPN of the user when interoperating with AD FS 1.1 or ADFS 1.0</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" Optional="true">
+ <auth:DisplayName>Role</auth:DisplayName>
+ <auth:Description>A role that the user has</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" Optional="true">
+ <auth:DisplayName>Surname</auth:DisplayName>
+ <auth:Description>The surname of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" Optional="true">
+ <auth:DisplayName>PPID</auth:DisplayName>
+ <auth:Description>The private identifier of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" Optional="true">
+ <auth:DisplayName>Name ID</auth:DisplayName>
+ <auth:Description>The SAML name identifier of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant" Optional="true">
+ <auth:DisplayName>Authentication time stamp</auth:DisplayName>
+ <auth:Description>Used to display the time and date that the user was authenticated</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod" Optional="true">
+ <auth:DisplayName>Authentication method</auth:DisplayName>
+ <auth:Description>The method used to authenticate the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid" Optional="true">
+ <auth:DisplayName>Deny only group SID</auth:DisplayName>
+ <auth:Description>The deny-only group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid" Optional="true">
+ <auth:DisplayName>Deny only primary SID</auth:DisplayName>
+ <auth:Description>The deny-only primary SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid" Optional="true">
+ <auth:DisplayName>Deny only primary group SID</auth:DisplayName>
+ <auth:Description>The deny-only primary group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid" Optional="true">
+ <auth:DisplayName>Group SID</auth:DisplayName>
+ <auth:Description>The group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid" Optional="true">
+ <auth:DisplayName>Primary group SID</auth:DisplayName>
+ <auth:Description>The primary group SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid" Optional="true">
+ <auth:DisplayName>Primary SID</auth:DisplayName>
+ <auth:Description>The primary SID of the user</auth:Description>
+ </auth:ClaimType>
+ <auth:ClaimType xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" Uri="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname" Optional="true">
+ <auth:DisplayName>Windows account name</auth:DisplayName>
+ <auth:Description>The domain account name of the user in the form of &lt;domain&gt;\&lt;user&gt;</auth:Description>
+ </auth:ClaimType>
+ </fed:ClaimTypesOffered>
+ <fed:SecurityTokenServiceEndpoint>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/services/trust/2005/certificatemixed</Address>
+ <Metadata>
+ <Metadata xmlns="http://schemas.xmlsoap.org/ws/2004/09/mex" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:wsx="http://schemas.xmlsoap.org/ws/2004/09/mex">
+ <wsx:MetadataSection xmlns="" Dialect="http://schemas.xmlsoap.org/ws/2004/09/mex">
+ <wsx:MetadataReference>
+ <Address xmlns="http://www.w3.org/2005/08/addressing">https://idp.chalmers.se/adfs/services/trust/mex</Address>
+ </wsx:MetadataReference>
+ </wsx:MetadataSection>
+ </Metadata>
+ </Metadata>
+ </EndpointReference>
+ </fed:SecurityTokenServiceEndpoint>
+ <fed:PassiveRequestorEndpoint>
+ <EndpointReference xmlns="http://www.w3.org/2005/08/addressing">
+ <Address>https://idp.chalmers.se/adfs/ls/</Address>
+ </EndpointReference>
+ </fed:PassiveRequestorEndpoint>
+ </md:RoleDescriptor>
+ <md:SPSSODescriptor WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+ <md:KeyDescriptor use="encryption">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEgjCCA2qgAwIBAgIRAJmWfwVBm8cQS1Ty7e6QuJgwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMTAxMjcwMDAwMDBaFw0xNDAxMjYyMzU5NTlaMF0xCzAJBgNVBAYTAlNFMSYwJAYDVQQKEx1DaGFsbWVycyBUZWtuaXNrYSBIb2dza29sYSBBQjEMMAoGA1UECxMDSVRTMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj5S9nh00xzrsXmphDbOz4RPwG0JONHrBtVOm6NNwTTQhl8eZSG4oIT/ATXAaQjGXAnz04HDShP6xKwsPN0wZTpuEci4XLlbUaWvcuefPAwGO8Be/HWEB03ilM+FLmJ55CYvpFfxbuElA30YzQcw2xU637g/+rshELRCMZB9Thp3j0tZ09sQTXbodnStm3hN0azuqvtXhZ63+q47GpocyiOlj7wHY6zZ4OfCj2YxFIeiLBBur6/mBKH3uA/xkuIv6NPAN+BI0L4iH1q+umCjeE/qfzWLO3Fe3ngYTWx0YFEIduRWCz7fyLUITNJBSK7YENFdIB0g8wXBWcTVpAv08RAgMBAAGjggFiMIIBXjAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQU6ZdOotf55GTP/djvkXZgjXBGSqQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBgGA1UdIAQRMA8wDQYLKwYBBAGyMQECAh0wOgYDVR0fBDMwMTAvoC2gK4YpaHR0cDovL2NybC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcmwwbQYIKwYBBQUHAQEEYTBfMDUGCCsGAQUFBzAChilodHRwOi8vY3J0LnRjcy50ZXJlbmEub3JnL1RFUkVOQVNTTENBLmNydDAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AudGNzLnRlcmVuYS5vcmcwGgYDVR0RBBMwEYIPaWRwLmNoYWxtZXJzLnNlMA0GCSqGSIb3DQEBBQUAA4IBAQBsPH77mopZLCpQgcrIYyZJfGKrXb7rQ4NNaBOR8o/KLNptvY7NPtOnu0HRJrYfZIx4Abj0VgDs/CBWSnBJQcE+aGMQmcPhrSDua9S5p+Cpq4AV7bhCRIovWPFPNQ7TTYRKCkFCmnkM/Y3EyliddxM1JsIL5rw+k8/O/KUJPCSff7yDsSmse5qUrJ12Nh+aG/MB4NknOJuAsLjs0HpIjdVTNFb9dbhrE+8x3AiL0Nk9G69gff1V7uxndvWhCoDUW3RVkpj9xssfHj4atp9F7t3q0bKdt7Y3HWQm8wpSJd7OUWI2WXbA6kjI2YZtFcUCOzy32crsMxLXKsHJyMp/XYyw</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEgjCCA2qgAwIBAgIRAJmWfwVBm8cQS1Ty7e6QuJgwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMTAxMjcwMDAwMDBaFw0xNDAxMjYyMzU5NTlaMF0xCzAJBgNVBAYTAlNFMSYwJAYDVQQKEx1DaGFsbWVycyBUZWtuaXNrYSBIb2dza29sYSBBQjEMMAoGA1UECxMDSVRTMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj5S9nh00xzrsXmphDbOz4RPwG0JONHrBtVOm6NNwTTQhl8eZSG4oIT/ATXAaQjGXAnz04HDShP6xKwsPN0wZTpuEci4XLlbUaWvcuefPAwGO8Be/HWEB03ilM+FLmJ55CYvpFfxbuElA30YzQcw2xU637g/+rshELRCMZB9Thp3j0tZ09sQTXbodnStm3hN0azuqvtXhZ63+q47GpocyiOlj7wHY6zZ4OfCj2YxFIeiLBBur6/mBKH3uA/xkuIv6NPAN+BI0L4iH1q+umCjeE/qfzWLO3Fe3ngYTWx0YFEIduRWCz7fyLUITNJBSK7YENFdIB0g8wXBWcTVpAv08RAgMBAAGjggFiMIIBXjAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQU6ZdOotf55GTP/djvkXZgjXBGSqQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBgGA1UdIAQRMA8wDQYLKwYBBAGyMQECAh0wOgYDVR0fBDMwMTAvoC2gK4YpaHR0cDovL2NybC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcmwwbQYIKwYBBQUHAQEEYTBfMDUGCCsGAQUFBzAChilodHRwOi8vY3J0LnRjcy50ZXJlbmEub3JnL1RFUkVOQVNTTENBLmNydDAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AudGNzLnRlcmVuYS5vcmcwGgYDVR0RBBMwEYIPaWRwLmNoYWxtZXJzLnNlMA0GCSqGSIb3DQEBBQUAA4IBAQBsPH77mopZLCpQgcrIYyZJfGKrXb7rQ4NNaBOR8o/KLNptvY7NPtOnu0HRJrYfZIx4Abj0VgDs/CBWSnBJQcE+aGMQmcPhrSDua9S5p+Cpq4AV7bhCRIovWPFPNQ7TTYRKCkFCmnkM/Y3EyliddxM1JsIL5rw+k8/O/KUJPCSff7yDsSmse5qUrJ12Nh+aG/MB4NknOJuAsLjs0HpIjdVTNFb9dbhrE+8x3AiL0Nk9G69gff1V7uxndvWhCoDUW3RVkpj9xssfHj4atp9F7t3q0bKdt7Y3HWQm8wpSJd7OUWI2WXbA6kjI2YZtFcUCOzy32crsMxLXKsHJyMp/XYyw</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEazCCA1OgAwIBAgIQYiCzN6Gt8LkhjGEzm+oYbzANBgkqhkiG9w0BAQUFADA2MQswCQYDVQQGEwJOTDEPMA0GA1UEChMGVEVSRU5BMRYwFAYDVQQDEw1URVJFTkEgU1NMIENBMB4XDTE0MDEyMDAwMDAwMFoXDTE3MDEyNDIzNTk1OVowPTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDmWN/0UvY2KySOfg77U+ORidbq0YyqVSUxTEN5HT0WRRF/k7bdhyNp1mf8OuzefbFbTRwUyqi8BaFSdGaB2ifbyYhprchRdBXQzfS9OSzKRWQrRPPJRc7YF+h0OR2Byjy9Wkm3qzOzbv96DSihNuyhd+q+jUBUoJ+MWAj+K1/rsghrvAcKtedADR+62QaCQCkD6Pv7+njyWWAA1cJAm5KoEzXqANi3SkTwqUYB6PCMKnUBsh/w0I6Qv5lD0i/OXCZJguPhcGM5M/wSZq6iDLdtZ/EDNm82UXO3j+zBFDLSbiWuh74+/dtOyJKYZn5q9lGbhVqvFs/smAztKUSHndmbAgMBAAGjggFsMIIBaDAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQUaL0QFrip30INB0btXzbf1qhorUswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMCIGA1UdIAQbMBkwDQYLKwYBBAGyMQECAh0wCAYGZ4EMAQIBMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3JsMG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLnRjcy50ZXJlbmEub3JnMBoGA1UdEQQTMBGCD2lkcC5jaGFsbWVycy5zZTANBgkqhkiG9w0BAQUFAAOCAQEAll6pgh+zFiNIwql7sPVIQqhOCRjz1fOYfJUNAQQKiNeiWtZHC0PU7gcdKUmyDEmvdVuvMjnmuBzMCmTwYWBroWPMJCoHvWQGGTElForaG2AU7ghASUeGn2rtXdnj62dbhNhuh/yZfywKmCbRoKYsQB6/6TkmkQcXm7teOqzq3jOjlnJmMCRRSM8z7ZDI6KkcX+FFfsNR9zp76Xi3T6hsfNQJOD593JA7Ub8rX2p3YQIYLNGARfR7fAQoSBgibcGX6buthzFl1Af+ghyy99nezrJ1srvD81AKG7a55znKBcQLPTTsqMlaG9tM9ERe/wQhf9zEUBPDB8PLmA+FfmR3Mg==</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.chalmers.se/adfs/ls/"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.chalmers.se/adfs/ls/"/>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.chalmers.se/adfs/ls/" index="0" isDefault="true"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://idp.chalmers.se/adfs/ls/" index="1"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.chalmers.se/adfs/ls/" index="2"/>
+ </md:SPSSODescriptor>
+ <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+ <md:Extensions>
+ <shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">chalmers.se</shibmd:Scope>
+ <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
+ <mdui:DisplayName xml:lang="sv">Chalmers</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">Chalmers</mdui:DisplayName>
+ <mdui:Description xml:lang="sv">Identity Provider för Chalmers</mdui:Description>
+ <mdui:Description xml:lang="en">Identity Provider for Chalmers</mdui:Description>
+ <mdui:InformationURL xml:lang="sv">http://www.chalmers.se/</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="en">http://www.chalmers.se/en/</mdui:InformationURL>
+ </mdui:UIInfo>
+ <mdui:DiscoHints xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
+ <mdui:DomainHint>chalmers.se</mdui:DomainHint>
+ <mdui:IPHint>129.16.0.0/16</mdui:IPHint>
+ <mdui:GeolocationHint>geo:57.6899722,11.9774444</mdui:GeolocationHint>
+ </mdui:DiscoHints>
+ </md:Extensions>
+ <md:KeyDescriptor use="encryption">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEgjCCA2qgAwIBAgIRAJmWfwVBm8cQS1Ty7e6QuJgwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMTAxMjcwMDAwMDBaFw0xNDAxMjYyMzU5NTlaMF0xCzAJBgNVBAYTAlNFMSYwJAYDVQQKEx1DaGFsbWVycyBUZWtuaXNrYSBIb2dza29sYSBBQjEMMAoGA1UECxMDSVRTMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj5S9nh00xzrsXmphDbOz4RPwG0JONHrBtVOm6NNwTTQhl8eZSG4oIT/ATXAaQjGXAnz04HDShP6xKwsPN0wZTpuEci4XLlbUaWvcuefPAwGO8Be/HWEB03ilM+FLmJ55CYvpFfxbuElA30YzQcw2xU637g/+rshELRCMZB9Thp3j0tZ09sQTXbodnStm3hN0azuqvtXhZ63+q47GpocyiOlj7wHY6zZ4OfCj2YxFIeiLBBur6/mBKH3uA/xkuIv6NPAN+BI0L4iH1q+umCjeE/qfzWLO3Fe3ngYTWx0YFEIduRWCz7fyLUITNJBSK7YENFdIB0g8wXBWcTVpAv08RAgMBAAGjggFiMIIBXjAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQU6ZdOotf55GTP/djvkXZgjXBGSqQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBgGA1UdIAQRMA8wDQYLKwYBBAGyMQECAh0wOgYDVR0fBDMwMTAvoC2gK4YpaHR0cDovL2NybC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcmwwbQYIKwYBBQUHAQEEYTBfMDUGCCsGAQUFBzAChilodHRwOi8vY3J0LnRjcy50ZXJlbmEub3JnL1RFUkVOQVNTTENBLmNydDAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AudGNzLnRlcmVuYS5vcmcwGgYDVR0RBBMwEYIPaWRwLmNoYWxtZXJzLnNlMA0GCSqGSIb3DQEBBQUAA4IBAQBsPH77mopZLCpQgcrIYyZJfGKrXb7rQ4NNaBOR8o/KLNptvY7NPtOnu0HRJrYfZIx4Abj0VgDs/CBWSnBJQcE+aGMQmcPhrSDua9S5p+Cpq4AV7bhCRIovWPFPNQ7TTYRKCkFCmnkM/Y3EyliddxM1JsIL5rw+k8/O/KUJPCSff7yDsSmse5qUrJ12Nh+aG/MB4NknOJuAsLjs0HpIjdVTNFb9dbhrE+8x3AiL0Nk9G69gff1V7uxndvWhCoDUW3RVkpj9xssfHj4atp9F7t3q0bKdt7Y3HWQm8wpSJd7OUWI2WXbA6kjI2YZtFcUCOzy32crsMxLXKsHJyMp/XYyw</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEgjCCA2qgAwIBAgIRAJmWfwVBm8cQS1Ty7e6QuJgwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMTAxMjcwMDAwMDBaFw0xNDAxMjYyMzU5NTlaMF0xCzAJBgNVBAYTAlNFMSYwJAYDVQQKEx1DaGFsbWVycyBUZWtuaXNrYSBIb2dza29sYSBBQjEMMAoGA1UECxMDSVRTMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCj5S9nh00xzrsXmphDbOz4RPwG0JONHrBtVOm6NNwTTQhl8eZSG4oIT/ATXAaQjGXAnz04HDShP6xKwsPN0wZTpuEci4XLlbUaWvcuefPAwGO8Be/HWEB03ilM+FLmJ55CYvpFfxbuElA30YzQcw2xU637g/+rshELRCMZB9Thp3j0tZ09sQTXbodnStm3hN0azuqvtXhZ63+q47GpocyiOlj7wHY6zZ4OfCj2YxFIeiLBBur6/mBKH3uA/xkuIv6NPAN+BI0L4iH1q+umCjeE/qfzWLO3Fe3ngYTWx0YFEIduRWCz7fyLUITNJBSK7YENFdIB0g8wXBWcTVpAv08RAgMBAAGjggFiMIIBXjAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQU6ZdOotf55GTP/djvkXZgjXBGSqQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMBgGA1UdIAQRMA8wDQYLKwYBBAGyMQECAh0wOgYDVR0fBDMwMTAvoC2gK4YpaHR0cDovL2NybC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcmwwbQYIKwYBBQUHAQEEYTBfMDUGCCsGAQUFBzAChilodHRwOi8vY3J0LnRjcy50ZXJlbmEub3JnL1RFUkVOQVNTTENBLmNydDAmBggrBgEFBQcwAYYaaHR0cDovL29jc3AudGNzLnRlcmVuYS5vcmcwGgYDVR0RBBMwEYIPaWRwLmNoYWxtZXJzLnNlMA0GCSqGSIb3DQEBBQUAA4IBAQBsPH77mopZLCpQgcrIYyZJfGKrXb7rQ4NNaBOR8o/KLNptvY7NPtOnu0HRJrYfZIx4Abj0VgDs/CBWSnBJQcE+aGMQmcPhrSDua9S5p+Cpq4AV7bhCRIovWPFPNQ7TTYRKCkFCmnkM/Y3EyliddxM1JsIL5rw+k8/O/KUJPCSff7yDsSmse5qUrJ12Nh+aG/MB4NknOJuAsLjs0HpIjdVTNFb9dbhrE+8x3AiL0Nk9G69gff1V7uxndvWhCoDUW3RVkpj9xssfHj4atp9F7t3q0bKdt7Y3HWQm8wpSJd7OUWI2WXbA6kjI2YZtFcUCOzy32crsMxLXKsHJyMp/XYyw</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+ <ds:X509Data>
+ <ds:X509Certificate>MIIEazCCA1OgAwIBAgIQYiCzN6Gt8LkhjGEzm+oYbzANBgkqhkiG9w0BAQUFADA2MQswCQYDVQQGEwJOTDEPMA0GA1UEChMGVEVSRU5BMRYwFAYDVQQDEw1URVJFTkEgU1NMIENBMB4XDTE0MDEyMDAwMDAwMFoXDTE3MDEyNDIzNTk1OVowPTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRgwFgYDVQQDEw9pZHAuY2hhbG1lcnMuc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDmWN/0UvY2KySOfg77U+ORidbq0YyqVSUxTEN5HT0WRRF/k7bdhyNp1mf8OuzefbFbTRwUyqi8BaFSdGaB2ifbyYhprchRdBXQzfS9OSzKRWQrRPPJRc7YF+h0OR2Byjy9Wkm3qzOzbv96DSihNuyhd+q+jUBUoJ+MWAj+K1/rsghrvAcKtedADR+62QaCQCkD6Pv7+njyWWAA1cJAm5KoEzXqANi3SkTwqUYB6PCMKnUBsh/w0I6Qv5lD0i/OXCZJguPhcGM5M/wSZq6iDLdtZ/EDNm82UXO3j+zBFDLSbiWuh74+/dtOyJKYZn5q9lGbhVqvFs/smAztKUSHndmbAgMBAAGjggFsMIIBaDAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fqkOO57TAdBgNVHQ4EFgQUaL0QFrip30INB0btXzbf1qhorUswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMCIGA1UdIAQbMBkwDQYLKwYBBAGyMQECAh0wCAYGZ4EMAQIBMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3JsMG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLnRjcy50ZXJlbmEub3JnMBoGA1UdEQQTMBGCD2lkcC5jaGFsbWVycy5zZTANBgkqhkiG9w0BAQUFAAOCAQEAll6pgh+zFiNIwql7sPVIQqhOCRjz1fOYfJUNAQQKiNeiWtZHC0PU7gcdKUmyDEmvdVuvMjnmuBzMCmTwYWBroWPMJCoHvWQGGTElForaG2AU7ghASUeGn2rtXdnj62dbhNhuh/yZfywKmCbRoKYsQB6/6TkmkQcXm7teOqzq3jOjlnJmMCRRSM8z7ZDI6KkcX+FFfsNR9zp76Xi3T6hsfNQJOD593JA7Ub8rX2p3YQIYLNGARfR7fAQoSBgibcGX6buthzFl1Af+ghyy99nezrJ1srvD81AKG7a55znKBcQLPTTsqMlaG9tM9ERe/wQhf9zEUBPDB8PLmA+FfmR3Mg==</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.chalmers.se/adfs/services/trust/artifactresolution" index="0"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.chalmers.se/adfs/ls/"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.chalmers.se/adfs/ls/"/>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+ <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.chalmers.se/adfs/ls/"/>
+ <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.chalmers.se/adfs/ls/"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="E-Mail Address"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Given Name"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Name"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="UPN"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/CommonName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Common Name"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/EmailAddress" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="AD FS 1.x E-Mail Address"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/Group" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Group"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/claims/UPN" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="AD FS 1.x UPN"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Role"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Surname"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="PPID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Name ID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Authentication time stamp"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Authentication method"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Deny only group SID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Deny only primary SID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarygroupsid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Deny only primary group SID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Group SID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarygroupsid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Primary group SID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Primary SID"/>
+ <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="Windows account name"/>
+ </md:IDPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">CHALMERS</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="sv">Chalmers</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="en">Chalmers</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">http://www.chalmers.se</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="technical">
+ <md:Company>Chalmers</md:Company>
+ <md:SurName>IT-system</md:SurName>
+ <md:EmailAddress>mailto:biorn@chalmers.se</md:EmailAddress>
+ <md:TelephoneNumber>+46 31 772 8658</md:TelephoneNumber>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:Company>Chalmers</md:Company>
+ <md:SurName>IT-support</md:SurName>
+ <md:EmailAddress>mailto:support@chalmers.se</md:EmailAddress>
+ <md:TelephoneNumber>+46 31 772 6000</md:TelephoneNumber>
+ </md:ContactPerson>
+</md:EntityDescriptor>